ApplyPAdESLongTermValidation

Assinaturas digitais

Descrição

Promove um PDF já assinado a PAdES-B-LT em uma única chamada, gravando o resultado em um arquivo

Sintaxe

Delphi

Function TPDFlib.ApplyPAdESLongTermValidation(Const InputFile, Password, OutputFile, FieldName: WideString; Options: Integer): Integer;

Parâmetros

InputFileThe signed PDF.
PasswordA senha para abri-lo, ou uma string vazia.
OutputFileThe augmented PDF to write.
FieldNameA signature field to process, or an empty string to process every signature into one revision.
OptionsA PADES_LTV_* bit mask; 0 selects PADES_LTV_DEFAULT.

Opções

PADES_LTV_WRITE_VRI (1)Gravar uma entrada VRI para cada assinatura.
PADES_LTV_FETCH_OCSP (2)Consultar o respondedor OCSP de cada link.
PADES_LTV_FETCH_CRL (4)Recorrer à CRL quando o OCSP não retornar nada.
PADES_LTV_FOLLOW_AIA (8)Seguir os endereços do emissor para completar o caminho.
PADES_LTV_SKIP_EXISTING (16)Do not re-add material whose bytes are already staged.
PADES_LTV_SKIP_ROOT_REVOCATION (32)Do not ask for a self-issued root's status.
PADES_LTV_DEFAULT (63)Tudo o que está acima; selecionado quando Options é 0.

Valores retornados

1The promotion succeeded.
2O arquivo de entrada não pôde ser lido.
3O PDF de entrada não pôde ser interpretado.
10A saída não pôde ser gravada.
11O document security store não pôde ser adicionado.
20No such signature field.
21No processed signature carried a readable certificate.

GetPAdESLTVError informa o motivo para qualquer valor diferente de 1.

Observações

The signer certificate path is built from the signature's own CMS, and the remaining issuers are followed through the caIssuers addresses the certificates name when PADES_LTV_FOLLOW_AIA is set. Revocation is gathered for each link - OCSP first, then a CRL - and, with the certificates, written into the document security store by a single incremental update.

Material idêntico ao que já foi preparado é gravado uma única vez e referenciado por todas as assinaturas que precisarem dele, de modo que uma certificate authority compartilhada ao longo do caminho ou entre assinaturas não aparece duplicada. Uma entrada VRI só é gravada quando tem um certificado para apontar, então nunca surge uma entrada vazia

Um respondedor inalcançável não faz a chamada falhar: a promoção segue com o que foi coletado, e GetPAdESLTVCertificateCount, GetPAdESLTVCRLCount, GetPAdESLTVOCSPCount e GetPAdESLTVError reportam o que foi obtido e o motivo de algo ter ficado de fora.

Exemplo

PDF.SetTimeStampOptions(2, 1, 1, 15000, '');
if PDF.ApplyPAdESLongTermValidation('signed.pdf', '', 'signed-lt.pdf', '', 0)<> 1 then
  ShowMessage(PDF.GetPAdESLTVError);

Veja também

ApplyPAdESLongTermValidationToStream, GetSignatureCertificateChainLength, AddPAdESDSSOCSPFromCertificates